Security policies
Name
Institution
Professor
Course
Date
Developing, Maintaining, and Security Policies
Security policies are rules set and enacted by an organization to ensure that all persons who use the company’s networks and other IT structures abide by the given security prescriptions. The policies aim to protect the firm’s sensitive information and other assets prone to theft cases. The policies are put in place to detect possible compromises and safeguard their reputation and customers (Hu et al., 2012). This paper discusses the processes involved in maintaining and updating policies and one important principle that should be considered when developing security policies.
The people responsible for maintaining and updating security policies should first identify the risks that should be expected. The information that is highly sensitive and risky to be seen by the public should be the topmost priority. The experts should know where the loopholes are, whether while sending and receiving files and attachments. The monitoring and reporting tools can be used to identify these risks before taking any other initiative. The employees should be aware of the security assessment through record taking from their activities (Stamp, 2011).
Employees play an essential role in maintaining security policies in an organization (Hu et al., 2012). Before putting in place the policies for maintenance, employees should be made aware of the construction process. Maintaining security policies will mean that many changes will have to take place on how the employees operate. They should be involved to give them a sense of ownership. They should sign the policies in paper to prove that they are ready to enforce and maintain the policies for the company’s greater good.
Good maintenance of the security policies demands for enough training programs among the staff members. Even though most managerial staff ignores this, it is the most paramount process because the staff members are the ones to keep the policies working (Puhakainen & Siponen, 2010). It helps the employees get the required knowledge and understanding of the policies. It also gives the IT experts a chance to discuss the policies’ implications in real life with the employees rather than just having them in the paper. The policies are more of a condition that comes with employment contracts. The employees should know the penalties that await them in case they compromise the security of the organization.
Privacy is the most important principle that needs to be considered when making and implementing security policies. The privacy principle relates to the integrity, confidentiality, and availability elements of information security policies (Stamp, 2011). Confidentiality states the kind of information that needs to be shared and those that should be kept as top secrets for the managerial staff. The integrity element states hoe the employees can access the company’s information safely without compromising the security. Maintaining high levels of privacy in an organization limits the cases of unauthorized information disclosure.
References
Hu, Q., Dinev, T., Hart, P., & Cooke, D. (2012). Managing employee compliance with information security policies: The critical role of top management and organizational culture. Decision Sciences, 43(4), 615-660.
Puhakainen, P., & Siponen, M. (2010). Improving employees’ compliance through information systems security training: an action research study. MIS quarterly, 757-778.
Stamp, M. (2011). Information security: principles and practice. John Wiley & Sons.